ID

VAR-201803-1607


CVE

CVE-2018-0188


TITLE

Cisco IOS XE Software cross-site scripting vulnerability

Trust: 1.4

sources: JVNDB: JVNDB-2018-003433 // CNNVD: CNNVD-201803-1008

DESCRIPTION

Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities are due to insufficient input validation of certain parameters that are passed to the affected software via the web UI. An attacker could exploit these vulnerabilities by persuading a user of the affected UI to access a malicious link or by intercepting a user request for the affected UI and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected UI or allow the attacker to access sensitive browser-based information on the user's system. Cisco Bug IDs: CSCuz38591, CSCvb09530, CSCvb10022. Vendors have confirmed this vulnerability Bug ID CSCuz38591 , CSCvb09530 ,and CSCvb10022 It is released as.Information may be obtained and information may be altered. Cisco IOSXESoftware is a set of operating systems developed by Cisco for its network devices. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 2.52

sources: NVD: CVE-2018-0188 // JVNDB: JVNDB-2018-003433 // CNVD: CNVD-2018-08002 // BID: 103551 // VULHUB: VHN-118390

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-08002

AFFECTED PRODUCTS

vendor:ciscomodel:ios xescope:ltversion:16.3.6

Trust: 1.0

vendor:ciscomodel:iosscope:eqversion:16.2

Trust: 0.9

vendor:ciscomodel:iosscope:eqversion:16.1.2

Trust: 0.9

vendor:ciscomodel:iosscope:eqversion:16.3(0)

Trust: 0.9

vendor:ciscomodel:ios xescope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xe softwarescope: - version: -

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5sq

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5s.1

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5s\(.1\)

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.6.0s

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5s_base

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5s.0

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.6.2s

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5s\(.2\)

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.5s.2

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:3.6.1s

Trust: 0.6

vendor:ciscomodel:ios xe softwarescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2018-08002 // BID: 103551 // JVNDB: JVNDB-2018-003433 // CNNVD: CNNVD-201803-1008 // NVD: CVE-2018-0188

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-0188
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-0188
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-08002
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201803-1008
value: MEDIUM

Trust: 0.6

VULHUB: VHN-118390
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-0188
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-08002
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-118390
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-0188
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-08002 // VULHUB: VHN-118390 // JVNDB: JVNDB-2018-003433 // CNNVD: CNNVD-201803-1008 // NVD: CVE-2018-0188

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-118390 // JVNDB: JVNDB-2018-003433 // NVD: CVE-2018-0188

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-1008

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201803-1008

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-003433

PATCH

title:cisco-sa-20180328-webuixssurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-webuixss

Trust: 0.8

title:Patch for Cisco IOSXE Cross-Site Scripting Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/126519

Trust: 0.6

title:Cisco IOS XE Software Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79476

Trust: 0.6

sources: CNVD: CNVD-2018-08002 // JVNDB: JVNDB-2018-003433 // CNNVD: CNNVD-201803-1008

EXTERNAL IDS

db:NVDid:CVE-2018-0188

Trust: 3.4

db:BIDid:103551

Trust: 2.6

db:JVNDBid:JVNDB-2018-003433

Trust: 0.8

db:CNNVDid:CNNVD-201803-1008

Trust: 0.7

db:CNVDid:CNVD-2018-08002

Trust: 0.6

db:VULHUBid:VHN-118390

Trust: 0.1

sources: CNVD: CNVD-2018-08002 // VULHUB: VHN-118390 // BID: 103551 // JVNDB: JVNDB-2018-003433 // CNNVD: CNNVD-201803-1008 // NVD: CVE-2018-0188

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20180328-webuixss

Trust: 2.6

url:http://www.securityfocus.com/bid/103551

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-0188

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-0188

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2018-08002 // VULHUB: VHN-118390 // BID: 103551 // JVNDB: JVNDB-2018-003433 // CNNVD: CNNVD-201803-1008 // NVD: CVE-2018-0188

CREDITS

Cisco

Trust: 0.3

sources: BID: 103551

SOURCES

db:CNVDid:CNVD-2018-08002
db:VULHUBid:VHN-118390
db:BIDid:103551
db:JVNDBid:JVNDB-2018-003433
db:CNNVDid:CNNVD-201803-1008
db:NVDid:CVE-2018-0188

LAST UPDATE DATE

2024-11-23T21:53:19.922000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-08002date:2018-04-20T00:00:00
db:VULHUBid:VHN-118390date:2019-10-09T00:00:00
db:BIDid:103551date:2018-03-28T00:00:00
db:JVNDBid:JVNDB-2018-003433date:2018-05-23T00:00:00
db:CNNVDid:CNNVD-201803-1008date:2019-10-17T00:00:00
db:NVDid:CVE-2018-0188date:2024-11-21T03:37:41.640

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-08002date:2018-04-19T00:00:00
db:VULHUBid:VHN-118390date:2018-03-28T00:00:00
db:BIDid:103551date:2018-03-28T00:00:00
db:JVNDBid:JVNDB-2018-003433date:2018-05-23T00:00:00
db:CNNVDid:CNNVD-201803-1008date:2018-03-29T00:00:00
db:NVDid:CVE-2018-0188date:2018-03-28T22:29:01.953